Skip to main content
Your research data is sensitive. Bower is built with security at every layer, from how data is stored and transmitted to how access is controlled and audited.

Encryption

In transit

All data between your browser and Bower’s servers is encrypted using TLS. This includes:
  • Every API request and response
  • File uploads and downloads
  • Real-time WebSocket connections
  • Voice and video streams in live agent mode
Every connection to Bower’s infrastructure is served over TLS.

At rest

All data at rest is encrypted using AES-256:
  • Database: all notes, collections, metadata, and user records are encrypted at the storage layer.
  • File storage: all uploaded files (images, audio, PDFs, documents) are encrypted at rest.
  • Backups: database backups are encrypted automatically.
Encryption keys are managed by the cloud infrastructure and are not accessible to application code.

Workspace isolation

Bower is multi-tenant: your data lives in a shared, encrypted database where every workspace’s data is isolated at the data layer, not just in the UI.
  • Queries for your workspace’s data are automatically scoped to it by a shared data-access layer, rather than that check being added route by route.
  • Workspace membership is verified on every request before any data is returned.
  • Files are stored in workspace-scoped paths and are only accessible via time-limited signed URLs (24-hour expiry).
  • Bower and search are scoped to your current workspace.
This scoping is applied automatically in that shared layer, so it isn’t something a developer has to remember to add on each new query. Separately, the endpoints that expose an individual note or project are covered by an automated test that fails our build if their access check is missing, so that protection can’t be dropped by adding a new route.

Authentication and access control

  • Token verification: every API request includes a signed authentication token that is verified server-side before any data is returned.
  • Email verification: unverified email addresses are blocked from accessing workspace data.
  • Token expiry: expired or revoked tokens are rejected immediately.
  • Role-based access: four roles (Owner, Admin, Member, Guest) with a strict hierarchy enforced at the API level.

Audit trail

Every create, update, and delete action in your workspace is logged with:
  • Who performed the action
  • What changed (field-level diffs with before and after values)
  • When it happened
  • The IP address and user agent of the request
Audit logs are accessible from the Audit log link in the sidebar (or directly at app.bowerlabs.ai/audit) and can be exported to CSV. See the audit logs guide for details.

AI processing

When Bower processes your data (voice transcription, photo text extraction, or Bower conversations), the content is sent to AI model providers for inference. Two separate commitments apply, and they protect different things:
  • Bower does not use your identifiable content to train AI models. Not ours, not anyone’s.
  • Our AI providers are contractually barred from training on it or retaining it for human review beyond what is needed to return a result.
The Terms of Service reserve a narrow right over data we have de-identified, which does not reach your results, findings, or inventions. The tests it has to pass, and what it covers today, are set out on AI & your data. Bower also retains AI request and response text for a limited period for quality monitoring. That is service operation, not training, and it is disclosed in full on AI & your data, along with which providers we use, where data goes in transit, and how to lock a workspace down. For every service that processes your data, see our sub-processor list.

Your data rights

You have full control over your personal data in Bower:
  • Export your data: download a complete copy of all your personal data (profile, workspaces, projects, artifacts, audit history) as a JSON file from Settings > Security > Export my data. This covers your data across all workspaces.
  • Delete your account: permanently remove your profile and all associated data. See the Deletion section below.
  • Cookie preferences: control which cookies Bower uses. See our cookie policy.
If you have questions about your data or want to exercise your rights, contact our Data Protection Officer at [email protected].

Deletion

When you delete notes, attachments, or collections, they are moved to trash for 30 days. During this period you can restore them from Trash in the sidebar. After 30 days, trashed items are automatically purged: they are removed from the database and are no longer reachable from Bower in any form. Backups take a little longer to catch up. Purged files are fully erased from file storage within about 37 days of the purge, and database backups are kept for about 30 days. These windows exist so we can recover from an outage or an accidental deletion. Nothing in them is reachable from the product, they are encrypted, and access is restricted to our operators.
  • Deleted notes and attachments are moved to trash. They are excluded from search, share links, and all normal views while in trash.
  • Deleting a collection moves all notes and sub-collections within it to trash.
  • Deleting your account permanently removes:
    • Your profile information (email, name)
    • Your workspace memberships and OAuth integrations
    • Your Firebase authentication record
    • Workspaces where you are the sole member (and all content and files within)
    In shared workspaces (where other members exist), your notes, files, and collections are kept for the team, and a workspace admin takes over administering them; ownership does not change. Only your membership is removed. Audit logs are anonymized (the record of what happened is preserved, but your identity is removed).
Account deletion skips trash and removes your data straight away, but the same backup windows described above still apply before it is fully erased. We recommend exporting your data before deleting your account.

Data protection officer

Our designated Data Protection Officer (DPO) is David Lyon. For any privacy-related questions, data subject requests, or concerns:
  • Email: [email protected]
  • Response time: We aim to respond to all requests within 30 days, as required by GDPR.

Further reading

Your responsibilities

  • Do not store credentials, passwords, or access tokens in notes.
  • Use workspace roles to control who can access your data.
  • Review the audit logs periodically if your workspace handles sensitive research data.
  • Use a strong, unique password for your Bower account.